CCPA Update: Who’s In Scope (Part 1)

Table of contents
The state of California has updated the California Consumer Privacy Act (CCPA) and its supporting regulations yet again. The California Privacy Protection Agency (CPPA) oversees compliance with these regulations. This post is the first in a series on CCPA and will cover what organizations CCPA does applies to, including a deep dive into the types of information covered by CCPA, and how CCPA is enforced.
TrustedSec has years of experience helping organizations implement and audit both cybersecurity and privacy requirements. Please get in touch with us for any questions on the applicability, scope, or requirements of CCPA or other compliance frameworks.
Overview
Applicability
CCPA applies to businesses that do business in the State of California and collect consumers’ personal information if they meet certain revenue and/or personal information processing thresholds.
Enforcement
CCPA is enforced by CPPA and directly by consumer action via a system of administrative fines and civil penalties for non-compliance as well as additional per-consumer, per-incident damages for breaches.
Applicability
CCPA Applicability
CCPA applies to “businesses,” which is defined in Cal. Civ. Code §1798.140(d) as all for-profit enterprises, including sole proprietorships, that do business in the State of California and collect, or cause others to collect on their behalf, consumers’ personal information (more on that definition below) if they meet any of the following criteria:
- Had annual gross revenues in excess of $26,625,000 (as of January 1, 2025) during the previous calendar year
- Buys, sells, or shares the personal information of 100,000 or more consumers or households annually, alone or in combination
- Derives 50% or more of its annual revenues from selling or sharing consumers' personal information
The gross revenue threshold shown above is adjusted for inflation every two (2) years. The CPPA publishes the current threshold.
CCPA also applies to:
- Entities that control or are controlled by a business that meets the criteria above and share common branding with that business
- Joint ventures and partnerships in which each business has at least a 40% interest
- Any person that voluntarily certifies that they comply with CCPA
Organizations that do not meet the definition of businesses shown above, either because they are not for profit, do not collect consumers’ personal information, or do not meet any of the thresholds, do not need to comply with CCPA or its cybersecurity audit requirement.
Among exemptions related to legal processes and consumer rights, CCPA also explicitly does not apply to:
- Healthcare providers and medical information governed by California’s Confidentiality of Medical Information Act
- HIPAA-covered entities and business associates, with respect to Protected Health Information (PHI) governed by the HIPAA Security, Breach Notification, and Privacy Rules
- Personal information collected as part of a clinical trial or other biomedical research study subject to the Federal Policy for the Protection of Human Subjects with certain conditions
- Consumer credit reporting
- Information subject to the Gramm-Leach-Bliley Act
- Information subject to the Driver’s Privacy Protection Act of 1994
There are many more exemptions and nuances than can be listed here, so organizations that feel they may be exempt should review the full list at Cal. Civ. Code §1798.145.
Personal Information
Some organizations may be confused about whether or not the information they handle meets the definition of personal information under CCPA. This is formally defined in Cal. Civ. Code §1798.140(v).
CCPA defines personal information as any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This explicitly includes (but is not limited to) the following:
|
The following are excluded from the definition of personal information:
|
“Publicly available” does not include biometric information collected by a business about a consumer without the consumer’s knowledge.
Some of the terms used in the definition of personal information (aggregate consumer information, biometric information, deidentified, inference, profiling, and unique personal identifier) are also further defined within Cal. Civ. Code §1798.140 for those who need it but are excluded here to keep this list from getting even longer.
Any information that meets the definition above is considered personal information regardless of what format it is in. CCPA explicitly lists the following formats as examples that are in scope:
Physical Formats | Digital Formats | Abstract Digital Formats |
|---|---|---|
Paper documents | Text files | Compressed files |
Printed images | Image files | Encrypted files |
Vinyl records | Audio files | Metadata |
Video tapes | Video files | Artificial intelligence systems that are capable of outputting personal information |
Sensitive Personal Information
Both the definition of personal information above and the applicability criteria for the CCPA cybersecurity audit requirement reference sensitive personal information, so it is important to understand this definition and how it differs from the definition of personal information. This is formally defined in Cal. Civ. Code §1798.140(ae) and includes:
|
Some of the terms used in the definition of sensitive personal information (biometric information, neural data, and precise geolocation) are also further defined within Cal. Civ. Code §1798.140 for those who need the details.
As with the definition of personal information, publicly available information is not considered sensitive personal information.
Enforcement
Non-compliance with CCPA is enforced via administrative fines and civil penalties of up to:
- $2,663 for each violation
- $7,988 for each intentional violation
- $7,988 for each violation involving the personal information of consumers under the age of 16
Businesses that are tempted to “fly under the radar” by avoiding compliance and hoping they don’t get caught should also be aware of additional penalties that apply following breaches of nonencrypted and nonredacted personal information. These fines are currently $107-$799 per-consumer, per-incident, or actual damages, whichever is greater. Breaches may also result in injunctive, declaratory, or any other relief a court deems proper. Consumers may initiate actions against a business for these statutory damages on an individual or class basis.
As with the gross revenue threshold for CCPA applicability, the fines are adjusted for inflation every two (2) years. The CPPA publishes the current thresholds.
The CPPA also has the power to launch investigations and conduct its own audits of businesses.